The Experts below are selected from a list of 1266 Experts worldwide ranked by ideXlab platform

Sharvari Patil - One of the best experts on this subject based on the ideXlab platform.

  • BRB dashboard: A web-based statistical dashboard
    2017 International Conference on Innovations in Information Embedded and Communication Systems (ICIIECS), 2017
    Co-Authors: Siddharth Mahajan, Mitesh Parekh, Hardik Patel, Sharvari Patil
    Abstract:

    Dashboards allow managers in keep track of various activities and developments in their departments. There are various existing enterprise resource planning systems that are standardized that can be used by trading sales industry. However there are various modules that are redundant to this industry that affect the speed and efficiency of the system. The proposed system is a statistical dashboard that not only keeps track of all the operations from client request to order delivery but also takes into consideration security of client data by enforcing various security mechanisms. The system has six modules including login module and five dashboards. The login module is secured using SHA256 hash to Store Password, variable salt and ReCaptcha mechanism. The five dashboards included in the system are Sourcing Dashboard, Accounts Dashboard, Operation Dashboard, Sales Dashboard and Admin Dashboard. The dashboard is tested to be secured from SQL Injection, Cross Site Scripting attack (XSS), Cross Site Request Forgery attack (CSRF), Brute Force and Session Fixation.

Zhiqiang Lin - One of the best experts on this subject based on the ideXlab platform.

  • ISPEC - Half a century of practice: Who is still storing plaintext Passwords?
    Information Security Practice and Experience, 2015
    Co-Authors: Erick Bauman, Zhiqiang Lin
    Abstract:

    Text-based Passwords are probably the most common way to authenticate a user on the Internet today. To implement a Password system, it is critical to ensure the confidentiality of the Stored Password—if an attacker obtains a Password, they get full access to that account. However, in the past several years, we have witnessed several major Password leakages in which all the Passwords were Stored in plaintext. Considering the severity of these security breaches, we believe that the website owners should have upgraded their systems to Store Password hashes. Unfortunately, there are still many websites that Store plaintext Passwords. Given the persistence of such bad practice, it is crucial to raise public awareness about this issue, find these websites, and shed light on best practices. As such, in this paper, we systematically analyze websites in both industry and academia and check whether they are still storing plaintext Passwords (or used to do so). In industry, we find 11 such websites in Alexa’s top 500 websites list. Also, we find this is a universal problem, regardless of the profile of the websites according to our analysis of almost 3,000 analyzed sites. Interestingly, we also find that even though end users have reported websites that are storing plaintext Passwords, significant amounts of website owners ignore this. On the academic side, our analysis of 135 conference submission sites shows that the majority of them are also still storing plaintext Passwords despite the existence of patches that fix this problem.

Siddharth Mahajan - One of the best experts on this subject based on the ideXlab platform.

  • BRB dashboard: A web-based statistical dashboard
    2017 International Conference on Innovations in Information Embedded and Communication Systems (ICIIECS), 2017
    Co-Authors: Siddharth Mahajan, Mitesh Parekh, Hardik Patel, Sharvari Patil
    Abstract:

    Dashboards allow managers in keep track of various activities and developments in their departments. There are various existing enterprise resource planning systems that are standardized that can be used by trading sales industry. However there are various modules that are redundant to this industry that affect the speed and efficiency of the system. The proposed system is a statistical dashboard that not only keeps track of all the operations from client request to order delivery but also takes into consideration security of client data by enforcing various security mechanisms. The system has six modules including login module and five dashboards. The login module is secured using SHA256 hash to Store Password, variable salt and ReCaptcha mechanism. The five dashboards included in the system are Sourcing Dashboard, Accounts Dashboard, Operation Dashboard, Sales Dashboard and Admin Dashboard. The dashboard is tested to be secured from SQL Injection, Cross Site Scripting attack (XSS), Cross Site Request Forgery attack (CSRF), Brute Force and Session Fixation.

Erick Bauman - One of the best experts on this subject based on the ideXlab platform.

  • ISPEC - Half a century of practice: Who is still storing plaintext Passwords?
    Information Security Practice and Experience, 2015
    Co-Authors: Erick Bauman, Zhiqiang Lin
    Abstract:

    Text-based Passwords are probably the most common way to authenticate a user on the Internet today. To implement a Password system, it is critical to ensure the confidentiality of the Stored Password—if an attacker obtains a Password, they get full access to that account. However, in the past several years, we have witnessed several major Password leakages in which all the Passwords were Stored in plaintext. Considering the severity of these security breaches, we believe that the website owners should have upgraded their systems to Store Password hashes. Unfortunately, there are still many websites that Store plaintext Passwords. Given the persistence of such bad practice, it is crucial to raise public awareness about this issue, find these websites, and shed light on best practices. As such, in this paper, we systematically analyze websites in both industry and academia and check whether they are still storing plaintext Passwords (or used to do so). In industry, we find 11 such websites in Alexa’s top 500 websites list. Also, we find this is a universal problem, regardless of the profile of the websites according to our analysis of almost 3,000 analyzed sites. Interestingly, we also find that even though end users have reported websites that are storing plaintext Passwords, significant amounts of website owners ignore this. On the academic side, our analysis of 135 conference submission sites shows that the majority of them are also still storing plaintext Passwords despite the existence of patches that fix this problem.

Mitesh Parekh - One of the best experts on this subject based on the ideXlab platform.

  • BRB dashboard: A web-based statistical dashboard
    2017 International Conference on Innovations in Information Embedded and Communication Systems (ICIIECS), 2017
    Co-Authors: Siddharth Mahajan, Mitesh Parekh, Hardik Patel, Sharvari Patil
    Abstract:

    Dashboards allow managers in keep track of various activities and developments in their departments. There are various existing enterprise resource planning systems that are standardized that can be used by trading sales industry. However there are various modules that are redundant to this industry that affect the speed and efficiency of the system. The proposed system is a statistical dashboard that not only keeps track of all the operations from client request to order delivery but also takes into consideration security of client data by enforcing various security mechanisms. The system has six modules including login module and five dashboards. The login module is secured using SHA256 hash to Store Password, variable salt and ReCaptcha mechanism. The five dashboards included in the system are Sourcing Dashboard, Accounts Dashboard, Operation Dashboard, Sales Dashboard and Admin Dashboard. The dashboard is tested to be secured from SQL Injection, Cross Site Scripting attack (XSS), Cross Site Request Forgery attack (CSRF), Brute Force and Session Fixation.